{
    "id": "CVE-2018-0823",
    "published": "2018-02-15 02:29:01",
    "last_modified": "2026-06-17 01:31:44",
    "cvss_score": "7.0",
    "cvss_severity": "HIGH",
    "cvss_version": "3.0",
    "cvss_vector": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
    "cwe": null,
    "description": "The Named Pipe File System in Windows 10 version 1709 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way the Named Pipe File System handles objects, aka \"Named Pipe File System Elevation of Privilege Vulnerability\".",
    "epss_score": "0.02633",
    "epss_percentile": "0.85122",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-10-10 18:17:17",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "microsoft",
            "product": "windows_10"
        },
        {
            "vendor": "microsoft",
            "product": "windows_server_2016"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "44148",
            "title": "Microsoft Windows - NPFS Symlink Security Feature Bypass/Elevation of Privilege/Dangerous Behavior",
            "date": "2018-02-20",
            "url": "https://www.exploit-db.com/exploits/44148"
        }
    ],
    "refs_list": [
        "http://www.securityfocus.com/bid/102919",
        "http://www.securitytracker.com/id/1040379",
        "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0823",
        "https://www.exploit-db.com/exploits/44148/",
        "http://www.securityfocus.com/bid/102919",
        "http://www.securitytracker.com/id/1040379",
        "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0823",
        "https://www.exploit-db.com/exploits/44148/"
    ]
}